HIGH

CVE-2021-24295

CVSS v3

7.5

HIGH

EPSS Score

45.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.153.4, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset.

Technical details

Published
5/17/2021

Frequently asked questions

What is CVE-2021-24295?

It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.153.4, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset.

Is CVE-2021-24295 actively exploited?

Active exploitation of CVE-2021-24295 has not been confirmed. The EPSS score is 45.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-24295?

CVE-2021-24295 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2021-24295 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.